Park microgrid trusted security self-adaptive method and system based on source network load storage constraint

CN122802145APending Publication Date: 2026-09-22WUXI XINENG REAL ESTATE MANAGEMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611093287.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-22
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0004]第一,现有设备身份认证多关注设备是否属于合法接入对象,缺少对设备硬件指纹、APP指纹、业务角色和接入区域的复合约束,难以解决园区微网中同类设备跨区域、跨业务越权接入的问题

Benefits of technology

[0080]1、本发明通过复合身份标识将设备身份、APP状态、业务角色和接入区域绑定,提升园区微网多类型设备可信接入能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802145A_ABST
    Figure CN122802145A_ABST
Patent Text Reader

Abstract

The application discloses a park microgrid reliable security strength self-adaptive method and system based on source network load storage operation constraint perception, comprising constructing a composite identity label integrating device hardware fingerprints, APP fingerprints, business roles and access areas, performing lightweight bidirectional authentication and remote timing verification on the edge side, checking power boundaries and energy storage SOC of control instructions by introducing physical constraint gating factors, and constructing a nonlinear business risk potential function combining grid-connected deviation and climbing risk. Further based on multi-dimensional trusted factor recursion, the device trustworthiness is updated, the reliable security strength is calculated by fusing physical gating, business risk and data sensitivity, the authentication strength, encryption level and abnormal handling strategy are adaptively switched, and the application realizes device trusted access and instruction trusted execution under cloud edge cooperation, and improves the active defense capability in park microgrid source network load storage cooperative scheduling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power Internet of Things and microgrid security protection technology, specifically to a trusted security adaptive method and system for campus microgrids based on source-grid-load-storage constraints. Background Technology

[0002] With the large-scale integration of distributed photovoltaic (PV) systems, energy storage systems, AC / DC charging piles, V2G charging piles, and flexible loads into park microgrids, these systems are evolving from traditional single-monitoring systems into multi-resource collaborative and interactive systems involving sources, grids, loads, and storage. Park microgrids involve diverse equipment types, communication protocols, business data, and control commands, requiring them to meet real-time requirements for data acquisition, operational monitoring, and collaborative scheduling, as well as security requirements for trusted equipment identities, reliable control commands, and secure transmission of business data.

[0003] Existing security technologies for microgrids or the power Internet of Things typically employ methods such as static account authentication, fixed certificate authentication, timestamp-based replay protection, link encryption, unified encryption policies, or general security gateway protection. While these methods can ensure communication link security to a certain extent, they still have the following shortcomings:

[0004] First, existing device authentication focuses primarily on whether a device is a legitimate access object, lacking a composite constraint on device hardware fingerprints, APP fingerprints, business roles, and access areas. This makes it difficult to solve the problem of unauthorized access by similar devices across regions and businesses in a campus micronet.

[0005] Second, existing control command security mechanisms mainly focus on signature, encryption, and replay protection, lacking joint verification of the semantics of control commands and the physical operational constraints of the source-grid-load-storage system. This makes it difficult to identify abnormal control behaviors where "the identity is legitimate but the command is unreasonable." For example, if a storage discharge command from a legitimate platform is executed when the storage SOC is too low, it may still pose a safety risk to the equipment.

[0006] Third, existing data encryption strategies typically employ fixed encryption levels, failing to adequately consider the dynamic changes in business type, data sensitivity, device trustworthiness, network link risks, and microgrid operation risks. This can easily lead to problems such as excessively high encryption overhead in low-risk scenarios and insufficient protection strength in high-risk scenarios.

[0007] Fourth, edge devices in park microgrids typically have limitations in computing, storage, and communication resources. If all authentication, command verification, and security decisions rely on the cloud, it will increase latency and cloud dependence, which is not conducive to source-grid-load-storage collaborative scheduling services at the minute or second level. Summary of the Invention

[0008] The purpose of this section is to outline some aspects of the embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.

[0009] The purpose of this invention is to provide a trusted security adaptive method and system for campus microgrids based on source-grid-load-storage constraints, which realizes lightweight authentication, trustworthiness recursion, trusted verification of control commands, dynamic key derivation, and hierarchical data encryption at the edge.

[0010] To address the technical problems mentioned in the background section, the present invention provides the following technical solution:

[0011] A trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints includes the following steps:

[0012] S1, the cloud security management center establishes security registration files for terminal devices, edge gateways, business apps and scheduling platforms in the park micronet, and generates composite identity identifiers including device hardware fingerprints, app fingerprints, business roles and access areas;

[0013] S2. The terminal device and the edge gateway perform lightweight two-way authentication based on the composite identity identifier, random number, timestamp, and initial key material.

[0014] S3. The edge gateway performs remote timing verification and serial number window verification on the terminal device, and establishes the initial trusted state of the device based on the authentication result, timing deviation, communication status and historical anomaly records.

[0015] S4. The edge gateway obtains the real-time operating status of the microgrid source, grid, load and storage in the park. The real-time operating status includes photovoltaic output, load power, energy storage SOC, V2G charging and discharging status, grid connection point power, control command target power and equipment power boundary.

[0016] S5. Based on the real-time operating status, construct a physical constraint gating factor. When the control command does not meet the physical operating constraints of the source-grid-load-storage system, directly refuse to execute the control command.

[0017] S6. Under the condition that the physical constraint gating passes, a nonlinear business risk potential function is constructed based on grid-connected power deviation risk, control power ramp-up risk, energy storage SOC boundary risk and communication link risk.

[0018] S7. Construct the current observation credibility of the device based on identity credibility, time credibility, communication credibility, data integrity credibility, and control command compliance credibility, and recursively update the device credibility by combining historical credibility and abnormal event penalty items;

[0019] S8 integrates physical constraint gating factors, nonlinear business risk potential functions, equipment trustworthiness, data sensitivity, and network link risks to calculate reliability and security strength.

[0020] S9. Adaptively select a security strategy based on the reliability and security strength. The security strategy includes a lightweight integrity verification strategy, a session key encryption strategy, a signature encryption and instruction constraint joint verification strategy, and a strong authentication, short-cycle key rotation, and access control isolation strategy.

[0021] S10: The edge gateway performs corresponding authentication, instruction trust verification, data encryption, integrity verification, key rotation, and anomaly handling operations on control commands and business data according to the selected security policy, and uploads security logs to the cloud security management center.

[0022] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints described in this invention, the composite identity identifier is represented as follows:

[0023] ;

[0024] in, Indicates the first A composite identity identifier for a device or app; Represents a hash function; Indicates the unique serial number of the device; Indicates a hardware fingerprint; Indicates the fingerprint of the APP; Indicates business role; Indicates the access area. This indicates a concatenation operation;

[0025] The specific steps for the terminal device and the edge gateway to perform lightweight two-way authentication based on the composite identity, random number, timestamp, and initial key material are as follows:

[0026] The terminal device initiates an access request to the edge gateway:

[0027] ;

[0028] in, Represents a terminal random number. Indicates the timestamp of the terminal device. Indicates business role, This represents the authentication digest, which is:

[0029] ;

[0030] The edge gateway verifies the device identity, business role, and APP fingerprint based on the registration profile issued by the cloud. After successful verification, the edge gateway returns an edge random number and an edge authentication digest to the terminal device to complete the two-way authentication.

[0031] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints described in this invention, the remote timing verification step is as follows:

[0032] The edge gateway sends a timing challenge message to the terminal device, and the terminal device returns the local time, a random number, and an authentication digest.

[0033] The edge gateway calculates the timing deviation based on the sending time, receiving time, and terminal return time:

[0034] ;

[0035] in, Indicates the first Timing deviation of individual devices; Indicates the local time returned by the terminal device; and These represent the times when the edge gateway sends the challenge message and receives the response message, respectively.

[0036] when When the timing verification passes; when At this time, the device enters a re-authentication, authorization restriction, or isolation process.

[0037] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints described in this invention, the physical constraint gating factor is:

[0038] ;

[0039] in, Indicates time Physical constraint gating factor, Indicates an indicator function; Indicates the target power of the control command. and These represent the lower and upper limits of the target device's allowable power, respectively. Indicates the state of charge of the energy storage. and These represent the lower and upper limits of the energy storage state of charge, respectively. Indicates the maximum permissible rate of power change Indicates the scheduling time interval. This indicates the actual grid-connected power value; Indicates the grid-connected power reference value. Indicates the allowable deviation of grid-connected power;

[0040] when When the edge gateway directly determines that the control command does not meet the source-network-load-storage operation constraints, it refuses to forward or execute the control command and generates a physical constraint anomaly alarm; when Meanwhile, the edge gateway continues to perform nonlinear business risk potential function calculation and reliable security strength adaptive decision-making.

[0041] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints described in this invention, the nonlinear business risk potential function is:

[0042] ;

[0043] in, Indicates time The business risk potential function value, This indicates the risk item related to grid-connected power deviation. This indicates the risk item related to power ramp-up control. This indicates the boundary risk item of energy storage SOC. Indicates communication link risk items, , , , This refers to the risk weighting coefficient.

[0044] ;

[0045] ;

[0046] ;

[0047] ;

[0048] in, Indicates the rated power of the microgrid or target device. This indicates the current packet loss rate of the link. This indicates the current link latency jitter. Indicates the message authentication failure rate. , , These represent the corresponding normalization upper limits.

[0049] As a preferred embodiment of the adaptive method for trusted security of a campus microgrid based on source-grid-load-storage constraints described in this invention, the device trustworthiness is calculated using a geometric fusion method, and the calculation steps are as follows:

[0050] First, calculate the confidence level of the current observation:

[0051] ;

[0052] in, Indicates the first Each device at time The current credibility of the observations; Indicates the credibility of the identity; Indicates the reliability of time synchronization; Indicates the reliability of the communication link; Indicates the reliability of data integrity; This indicates the compliance and credibility of control instructions; These are the exponential coefficients of each credibility factor;

[0053] Then, the device trustworthiness is updated recursively based on historical trustworthiness and anomaly penalty items:

[0054] ;

[0055] in, Indicates the first Each device at time The reliability of the equipment. This indicates the device's reliability at the previous moment. Indicates the historical memory coefficient. Indicates the current observation confidence level Indicates the first Has a class of exceptions occurred? Indicates the first Intensity of punishment for abnormal events This represents a truncation function that limits the confidence level to a preset range.

[0056] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-network-load-storage constraints described in this invention, the abnormal events include one or more of the following: identity authentication failure, inconsistent APP fingerprint, abnormal timing deviation, serial number rollback, message authentication code verification failure, inconsistent control command semantic digest, control command physical constraint gating failure, abnormal communication frequency, and abnormal service operation status.

[0057] As a preferred embodiment of the adaptive method for trusted security of a campus microgrid based on source-grid-load-storage constraints described in this invention, the formula for calculating the reliable security strength is as follows:

[0058] ;

[0059] in, Indicates time Reliable safety strength; Indicates the physical constraint gating factor; Indicates the reliability of the equipment; This represents the business risk potential function value; Indicates data sensitivity; Indicates network link risk. The larger the value, the higher the current need for enhanced security.

[0060] Security policies are adaptively selected based on the strength of reliable security:

[0061]

[0062] in, Indicates time The security strategy adopted This indicates a lightweight integrity verification strategy. Indicates the session key encryption strategy. This indicates a joint verification strategy involving signature, encryption, time window, and instruction constraints. This indicates a strong authentication, short-cycle key rotation, control restrictions, or device isolation policy. , , This indicates the threshold for switching security policies.

[0063] As a preferred embodiment of the trusted security adaptive method for campus microgrids based on source-network-load-storage constraints described in this invention, the edge gateway performs the following steps on control commands and service data according to the selected security policy: identity authentication, command trust verification, data encryption, integrity verification, key rotation, and anomaly handling.

[0064] Session keys are derived from the device composite identity, a random number, device trustworthiness, security policies, and policy versions.

[0065] ;

[0066] in, Indicates the first Each device at time Dynamic session key, This represents the key derivation function. This indicates the initial key material for the device. Represents a terminal random number. Represents a random number for the edge gateway. Represents the communication sequence number; Indicates the version of the cloud security policy;

[0067] The edge gateway encrypts, authenticates, and protects the integrity of different business data and control commands according to the selected security policy. The message authentication code is:

[0068] ;

[0069] in, Indicates the message authentication code. Indicates the message header, Indicates message payload, Represents a timestamp. Indicates the serial number. This indicates the current security policy.

[0070] A trusted security adaptive system for a campus microgrid based on source-network-load-storage constraints includes a cloud security management center, an edge security gateway, a terminal security agent, a control command trusted verification module, a business risk potential function calculation module, a device trustworthiness recursion module, a security policy adaptive decision-making module, and a log auditing module.

[0071] The cloud-based security management center is used to perform device registration, composite identity management, policy version management, and global trustworthiness updates.

[0072] The edge security gateway is used to perform two-way authentication, remote timing verification, dynamic session key derivation, trusted verification of control commands, data encryption, and anomaly handling.

[0073] The terminal security agent is deployed in photovoltaic inverters, energy storage cabinets, charging piles, V2G charging piles, flexible load controllers or microgrid monitoring devices to complete identity authentication response, data encryption upload, control command decryption verification and execution result feedback.

[0074] The control command trust verification module is used to verify the identity legitimacy, time validity, semantic consistency, and physical executability of control commands.

[0075] The business risk potential function calculation module is used to calculate the nonlinear business risk potential function;

[0076] The device credibility recursion module is used to update the device credibility based on the current observation credibility, historical credibility, and abnormal event penalty items;

[0077] The security policy adaptive decision-making module is used to select a security policy based on the reliability and security strength.

[0078] The log auditing module is used to record authentication logs, timing verification logs, key rotation logs, instruction verification logs, encrypted transmission logs, and exception handling logs.

[0079] Compared with the prior art, the beneficial effects of the present invention are:

[0080] 1. This invention binds device identity, APP status, business role and access area through composite identity identification, thereby improving the trusted access capability of multiple types of devices in the park micronetwork.

[0081] 2. This invention proposes a physical constraint gating mechanism, which introduces the physical operation constraints of source, grid, load and storage into the security verification of control commands, and can identify abnormal control commands that are legally valid but do not meet the operation status constraints.

[0082] 3. This invention proposes a nonlinear business risk potential function, which avoids the problem that simple weighted scoring cannot reflect the sudden increase in critical risk, and can more accurately characterize the risk changes when the operation status of the park microgrid approaches the safety boundary.

[0083] 4. This invention proposes a device trustworthiness recursive model, which designs the device trustworthiness status as a dynamic variable that changes over time, and can be dynamically updated based on historical trustworthiness status and current abnormal events.

[0084] 5. This invention proposes a reliable security strength adaptive decision-making mechanism, which enables the identity authentication strength, instruction verification depth, encryption level, key rotation cycle and anomaly handling strategy to dynamically change with business risks and device trustworthiness.

[0085] 6. This invention enables rapid and secure decision-making at the edge, reduces cloud dependence and communication latency, and is suitable for minute-level or second-level collaborative control scenarios of microgrid source-grid-load-storage in industrial parks. Attached Figure Description

[0086] To more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and detailed embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0087] Figure 1 The overall architecture diagram of the trusted security adaptive system for a campus microgrid based on source-grid-load-storage constraints provided by the present invention;

[0088] Figure 2 The present invention provides a flowchart for the construction of composite identity identifiers and edge-side two-way identity authentication.

[0089] Figure 3 The flowchart for remote timing verification provided by this invention;

[0090] Figure 4 The flowchart for physical constraint gating and control command reliability verification provided by this invention;

[0091] Figure 5 The flowchart for calculating the nonlinear business risk potential function provided by this invention;

[0092] Figure 6 The device reliability derivation flowchart provided by this invention;

[0093] Figure 7 The flowchart for the reliable security strength adaptive strategy switching provided by this invention;

[0094] Figure 8 The flowchart for dynamic session key derivation provided by this invention;

[0095] Figure 9 The flowchart for anomaly handling and cloud-edge collaboration strategy update provided by this invention. Detailed Implementation

[0096] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0097] The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints includes the following steps:

[0098] S1, the cloud security management center establishes security registration files for terminal devices, edge gateways, business apps and scheduling platforms in the park micronet, and generates composite identity identifiers including device hardware fingerprints, app fingerprints, business roles and access areas;

[0099] S2. The terminal device and the edge gateway perform lightweight two-way authentication based on the composite identity identifier, random number, timestamp, and initial key material.

[0100] S3. The edge gateway performs remote timing verification and serial number window verification on the terminal device, and establishes the initial trusted state of the device based on the authentication result, timing deviation, communication status and historical anomaly records.

[0101] S4. The edge gateway obtains the real-time operating status of the microgrid source, grid, load and storage in the park. The real-time operating status includes photovoltaic output, load power, energy storage SOC, V2G charging and discharging status, grid connection point power, control command target power and equipment power boundary.

[0102] S5. Based on the real-time operating status, construct a physical constraint gating factor. When the control command does not meet the physical operating constraints of the source-grid-load-storage system, directly refuse to execute the control command.

[0103] S6. Under the condition that the physical constraint gating passes, a nonlinear business risk potential function is constructed based on grid-connected power deviation risk, control power ramp-up risk, energy storage SOC boundary risk and communication link risk.

[0104] S7. Construct the current observation credibility of the device based on identity credibility, time credibility, communication credibility, data integrity credibility, and control command compliance credibility, and recursively update the device credibility by combining historical credibility and abnormal event penalty items;

[0105] S8 integrates physical constraint gating factors, nonlinear business risk potential functions, equipment trustworthiness, data sensitivity, and network link risks to calculate reliability and security strength.

[0106] S9. Adaptively select a security strategy based on the reliability and security strength. The security strategy includes a lightweight integrity verification strategy, a session key encryption strategy, a signature encryption and instruction constraint joint verification strategy, and a strong authentication, short-cycle key rotation, and access control isolation strategy.

[0107] S10: The edge gateway performs corresponding authentication, instruction trust verification, data encryption, integrity verification, key rotation, and anomaly handling operations on control commands and business data according to the selected security policy, and uploads security logs to the cloud security management center.

[0108] like Figure 2 As shown, the composite identity identifier is represented as follows:

[0109] ;

[0110] in, Indicates the first A composite identity identifier for a device or app; Represents a hash function; Indicates the unique serial number of the device; Indicates a hardware fingerprint; Indicates the fingerprint of the APP; Indicates business role; Indicates the access area. This indicates a concatenation operation;

[0111] The specific steps for the terminal device and the edge gateway to perform lightweight two-way authentication based on the composite identity, random number, timestamp, and initial key material are as follows:

[0112] The terminal device initiates an access request to the edge gateway:

[0113] ;

[0114] in, Represents a terminal random number. Indicates the timestamp of the terminal device. Indicates business role, This represents the authentication digest, which is:

[0115] ;

[0116] The edge gateway verifies the device identity, business role, and APP fingerprint based on the registration profile issued by the cloud. After successful verification, the edge gateway returns an edge random number and an edge authentication digest to the terminal device to complete the two-way authentication.

[0117] like Figure 3 The remote timing verification step is as follows:

[0118] The edge gateway sends a timing challenge message to the terminal device, and the terminal device returns the local time, a random number, and an authentication digest.

[0119] The edge gateway calculates the timing deviation based on the sending time, receiving time, and terminal return time:

[0120] ;

[0121] in, Indicates the first Timing deviation of individual devices; Indicates the local time returned by the terminal device; and These represent the times when the edge gateway sends the challenge message and receives the response message, respectively.

[0122] when When the timing verification passes; when At this time, the device enters a re-authentication, authorization restriction, or isolation process.

[0123] The physical constraint gating factor is:

[0124] ;

[0125] in, Indicates time Physical constraint gating factor, Indicates an indicator function; Indicates the target power of the control command. and These represent the lower and upper limits of the target device's allowable power, respectively. Indicates the state of charge of the energy storage. and These represent the lower and upper limits of the energy storage state of charge, respectively. Indicates the maximum permissible rate of power change Indicates the scheduling time interval. This indicates the actual grid-connected power value; Indicates the grid-connected power reference value. Indicates the allowable deviation of grid-connected power;

[0126] like Figure 4 As shown, when When the edge gateway directly determines that the control command does not meet the source-network-load-storage operation constraints, it refuses to forward or execute the control command and generates a physical constraint anomaly alarm; when Meanwhile, the edge gateway continues to perform nonlinear business risk potential function calculation and reliable security strength adaptive decision-making.

[0127] like Figure 5 As shown, the nonlinear business risk potential function is:

[0128] ;

[0129] in, Indicates time The business risk potential function value, This indicates the risk item related to grid-connected power deviation. This indicates the risk item related to power ramp-up control. This indicates the boundary risk item of energy storage SOC. Indicates communication link risk items, , , , This refers to the risk weighting coefficient.

[0130] ;

[0131] ;

[0132] ;

[0133] ;

[0134] in, Indicates the rated power of the microgrid or target device. This indicates the current packet loss rate of the link. This indicates the current link latency jitter. Indicates the message authentication failure rate. , , These represent the corresponding normalization upper limits.

[0135] like Figure 6 As shown, the reliability of the device is calculated using a geometric fusion method, and the calculation steps are as follows:

[0136] First, calculate the confidence level of the current observation:

[0137] ;

[0138] in, Indicates the first Each device at time The current credibility of the observations; Indicates the credibility of the identity; Indicates the reliability of time synchronization; Indicates the reliability of the communication link; Indicates the reliability of data integrity; This indicates the compliance and credibility of control instructions; These are the exponential coefficients of each credibility factor;

[0139] Then, the device trustworthiness is updated recursively based on historical trustworthiness and anomaly penalty items:

[0140] ;

[0141] in, Indicates the first Each device at time The reliability of the equipment. This indicates the device's reliability at the previous moment. Indicates the historical memory coefficient. Indicates the current observation confidence level Indicates the first Has a class of exceptions occurred? Indicates the first Intensity of punishment for abnormal events This represents a truncation function that limits the confidence level to a preset range.

[0142] The abnormal events include one or more of the following: identity authentication failure, inconsistent APP fingerprint, abnormal timing deviation, serial number rollback, message authentication code verification failure, inconsistent control command semantic digest, control command physical constraint gating failure, abnormal communication frequency, and abnormal business operation status.

[0143] The formula for calculating reliable safety strength is:

[0144] ;

[0145] in, Indicates time Reliable safety strength; Indicates the physical constraint gating factor; Indicates the reliability of the equipment; This represents the business risk potential function value; Indicates data sensitivity; Indicates network link risk. The larger the value, the higher the current need for enhanced security.

[0146] like Figure 7 As shown, the security policy is adaptively selected based on the reliability and security strength:

[0147]

[0148] in, Indicates time The security strategy adopted This indicates a lightweight integrity verification strategy. Indicates the session key encryption strategy. This indicates a joint verification strategy involving signature, encryption, time window, and instruction constraints. This indicates a strong authentication, short-cycle key rotation, control restrictions, or device isolation policy. , , This indicates the threshold for switching security policies.

[0149] like Figure 8 As shown, the session key is derived based on the device composite identity, a random number, device trustworthiness, security policy, and policy version:

[0150] ;

[0151] in, Indicates the first Each device at time Dynamic session key, This represents the key derivation function. This indicates the initial key material for the device. Represents a terminal random number. Represents a random number for the edge gateway. Represents the communication sequence number; Indicates the version of the cloud security policy;

[0152] The edge gateway encrypts, authenticates, and protects the integrity of different business data and control commands according to the selected security policy. The message authentication code is:

[0153] ;

[0154] in, Indicates the message authentication code. Indicates the message header, Indicates message payload, Represents a timestamp. Indicates the serial number. This indicates the current security policy.

[0155] like Figure 9As shown, when an edge gateway detects that a device's trustworthiness is below a threshold, the business risk potential function exceeds a threshold, the reliability and security strength reaches the highest level, or the physical constraint gating of control commands fails, and at least one of the above conditions is met, the following actions are taken according to the policy level: record the anomaly log; require the device to re-authenticate; upgrade the data encryption level; shorten the key rotation cycle; restrict the device's control permissions; isolate the device's communication link; report to the cloud security management center; and trigger manual review. The cloud security management center updates the global security policy based on the security logs uploaded by multiple edge gateways and issues the new policy version to the edge gateways.

[0156] like Figure 1 As shown, the present invention also provides a trusted security adaptive system for a campus microgrid based on source-network-load-storage constraints, including a cloud security management center, an edge security gateway, a terminal security agent, a control command trusted verification module, a business risk potential function calculation module, a device trustworthiness recursion module, a security policy adaptive decision-making module, and a log auditing module;

[0157] The cloud-based security management center is used to perform device registration, composite identity management, policy version management, and global trustworthiness updates.

[0158] The edge security gateway is used to perform two-way authentication, remote timing verification, dynamic session key derivation, trusted verification of control commands, data encryption, and anomaly handling.

[0159] The terminal security agent is deployed in photovoltaic inverters, energy storage cabinets, charging piles, V2G charging piles, flexible load controllers or microgrid monitoring devices to complete identity authentication response, data encryption upload, control command decryption verification and execution result feedback.

[0160] The control command trust verification module is used to verify the identity legitimacy, time validity, semantic consistency, and physical executability of control commands.

[0161] The business risk potential function calculation module is used to calculate the nonlinear business risk potential function;

[0162] The device credibility recursion module is used to update the device credibility based on the current observation credibility, historical credibility, and abnormal event penalty items;

[0163] The security policy adaptive decision-making module is used to select a security policy based on the reliability and security strength.

[0164] The log auditing module is used to record authentication logs, timing verification logs, key rotation logs, instruction verification logs, encrypted transmission logs, and exception handling logs.

[0165] To verify the technical effects of the present invention, the following five specific embodiments are provided.

[0166] Example 1: Composite Identity Authentication in Energy Storage Cabinet Access Scenarios

[0167] Within the park's microgrid, energy storage cabinets are connected to the source-load-storage collaborative control system via an edge security gateway. The cloud-based security management center pre-registers the energy storage cabinet's unique device number, hardware fingerprint, APP program fingerprint, affiliated transformer area, business role, and initial key materials.

[0168] The composite identification of the energy storage cabinet is as follows:

[0169] ;

[0170] When an energy storage cabinet connects to an edge gateway, the edge gateway verifies whether its hardware fingerprint, app fingerprint, and business role match the registration profile in the cloud. If the hardware fingerprint matches but the app fingerprint has changed, it indicates a risk of app tampering. The edge gateway then refuses access to the device and uploads the anomaly information to the cloud security management center.

[0171] Example 2: Physical Constraint Gating of Energy Storage Discharge Commands

[0172] When the cloud-based dispatch platform issues an energy storage discharge command, the edge gateway first verifies the signature, timestamp, and sequence number. After successful verification, it further reads the current energy storage SOC, discharge power limit, grid connection point power, and control power at the previous moment.

[0173] If the current energy storage SOC is lower than the SOC min ,but:

[0174] ;

[0175] therefore, The edge gateway directly rejects the energy storage discharge command and generates a safety alarm stating that "the control command does not meet the energy storage SOC boundary constraints." This process prevents legitimate control entities from issuing control commands that could compromise the safety of energy storage devices under unreasonable operating conditions.

[0176] Example 3: Nonlinear Risk Assessment of V2G Charging and Discharging Services

[0177] In V2G charging and discharging scenarios, vehicle SOC, charging and discharging power, and grid connection point power all exhibit strong dynamics. The edge gateway calculates the grid connection power deviation risk item:

[0178] ;

[0179] When the grid-connected power deviation is small, the risk potential function grows slowly; when the grid-connected power deviation approaches or exceeds the allowable range, the squared term and the exponential function work together to increase the risk potential function. The rapid escalation triggers a higher level of security policy.

[0180] For example, when When the reliability of the equipment increases and the reliability of the equipment decreases, the reliability security strength is reduced. Increase, the system uses a session key encryption strategy Automatically switch to a joint verification strategy of signature, encryption, time window, and instruction constraint. .

[0181] Example 4: Device Reliability Recursion and Anomaly Penalty

[0182] During continuous operation, a charging station experienced serial number rollback and message authentication code verification failure. The edge gateway recorded the corresponding abnormal events:

[0183] ;

[0184] Device trustworthiness updated to:

[0185] ;

[0186] Due to the existence of anomaly event penalties, the device's trustworthiness decreases. If the device's trustworthiness falls below a set threshold, the edge gateway restricts the charging station from accepting active power regulation control commands and requires it to re-authenticate.

[0187] Example 5: Reliability and security strength adaptive switching

[0188] For routine operational monitoring data, when equipment reliability is high, business risk is low, and data sensitivity is low, the reliability and security strength is [not specified]. Below The system adopts a lightweight integrity verification strategy. .

[0189] For energy storage control commands, when data sensitivity is high, the risk of control power ramp-up increases, and equipment reliability decreases, the reliability and safety strength is crucial. Enter Within the specified range, the system employs a joint verification strategy combining signature, encryption, time window, and instruction constraints. .

[0190] When consecutive authentication failures, physical constraint gating failures, or a significant increase in communication link risk occur, the reliability and security strength is affected. The system employs strong authentication, short-cycle key rotation, control restrictions, or device isolation strategies. .

[0191] Although the present invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the disclosed embodiments can be combined with each other in any manner. The lack of an exhaustive description of these combinations in this specification is merely for the sake of brevity and resource conservation. Therefore, the present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.

Claims

1. A trusted security adaptive method for campus microgrids based on source-grid-load-storage constraints, characterized in that, The steps include the following: S1, the cloud security management center establishes security registration files for terminal devices, edge gateways, business apps and scheduling platforms in the park micronet, and generates composite identity identifiers including device hardware fingerprints, app fingerprints, business roles and access areas; S2. The terminal device and the edge gateway perform lightweight two-way authentication based on the composite identity identifier, random number, timestamp, and initial key material. S3. The edge gateway performs remote timing verification and serial number window verification on the terminal device, and establishes the initial trusted state of the device based on the authentication result, timing deviation, communication status and historical anomaly records. S4. The edge gateway obtains the real-time operating status of the microgrid source, grid, load and storage in the park. The real-time operating status includes photovoltaic output, load power, energy storage SOC, V2G charging and discharging status, grid connection point power, control command target power and equipment power boundary. S5. Based on the real-time operating status, construct a physical constraint gating factor. When the control command does not meet the physical operating constraints of the source-grid-load-storage system, directly refuse to execute the control command. S6. Under the condition that the physical constraint gating passes, a nonlinear business risk potential function is constructed based on grid-connected power deviation risk, control power ramp-up risk, energy storage SOC boundary risk and communication link risk. S7. Construct the current observation credibility of the device based on identity credibility, time credibility, communication credibility, data integrity credibility, and control command compliance credibility, and recursively update the device credibility by combining historical credibility and abnormal event penalty items; S8 integrates physical constraint gating factors, nonlinear business risk potential functions, equipment trustworthiness, data sensitivity, and network link risks to calculate reliability and security strength. S9. Adaptively select a security strategy based on the reliability and security strength. The security strategy includes a lightweight integrity verification strategy, a session key encryption strategy, a signature encryption and instruction constraint joint verification strategy, and a strong authentication, short-cycle key rotation, and access control isolation strategy. S10, the edge gateway performs corresponding identity authentication, command trust verification, data encryption, integrity verification, key rotation and anomaly handling operations on control commands and business data according to the selected security policy, and uploads security logs to the cloud security management center.

2. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The composite identity identifier is represented as follows: ; in, Indicates the first A composite identity identifier for a device or app; Represents a hash function; Indicates the unique serial number of the device; Indicates a hardware fingerprint; Indicates the fingerprint of the APP; Indicates business role; Indicates the access area. This indicates a concatenation operation; The specific steps for the terminal device and the edge gateway to perform lightweight two-way authentication based on the composite identity, random number, timestamp, and initial key material are as follows: The terminal device initiates an access request to the edge gateway: ; in, Represents a terminal random number. Indicates the timestamp of the terminal device. Indicates business role, This represents the authentication digest, which is: ; The edge gateway verifies the device identity, business role, and APP fingerprint based on the registration profile issued by the cloud. After successful verification, the edge gateway returns an edge random number and an edge authentication digest to the terminal device to complete the two-way authentication.

3. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The remote timing verification step is as follows: The edge gateway sends a timing challenge message to the terminal device, and the terminal device returns the local time, a random number, and an authentication digest. The edge gateway calculates the timing deviation based on the sending time, receiving time, and terminal return time: ; in, Indicates the first Timing deviation of individual devices; Indicates the local time returned by the terminal device; and These represent the times when the edge gateway sends the challenge message and receives the response message, respectively. when When the timing verification passes; when At this time, the device enters a re-authentication, authorization restriction, or isolation process.

4. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The physical constraint gating factor is: ; in, Indicates time Physical constraint gating factor, Indicates an indicator function; Indicates the target power of the control command. and These represent the lower and upper limits of the target device's allowable power, respectively. Indicates the state of charge of the energy storage. and These represent the lower and upper limits of the energy storage state of charge, respectively. Indicates the maximum permissible rate of power change Indicates the scheduling time interval. This indicates the actual grid-connected power value; Indicates the grid-connected power reference value. Indicates the allowable deviation of grid-connected power; when When the edge gateway directly determines that the control command does not meet the source-network-load-storage operation constraints, it refuses to forward or execute the control command and generates a physical constraint anomaly alarm; when Meanwhile, the edge gateway continues to perform nonlinear business risk potential function calculation and reliable security strength adaptive decision-making.

5. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The nonlinear business risk potential function is: ; in, Indicates time The business risk potential function value, This indicates the risk item related to grid-connected power deviation. This indicates the risk item related to power ramp-up control. This indicates the boundary risk item of energy storage SOC. Indicates communication link risk items, , , , This refers to the risk weighting coefficient. ; ; ; ; in, Indicates the rated power of the microgrid or target device. This indicates the current packet loss rate of the link. This indicates the current link latency jitter. Indicates the message authentication failure rate. , , These represent the corresponding normalization upper limits.

6. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The device reliability is calculated using a geometric fusion method, and the calculation steps are as follows: First, calculate the confidence level of the current observation: ; in, Indicates the first Each device at time The current credibility of the observations; Indicates the credibility of the identity; Indicates the reliability of time synchronization; Indicates the reliability of the communication link; Indicates the reliability of data integrity; This indicates the compliance and credibility of control instructions; These are the exponential coefficients of each credibility factor; Then, the device trustworthiness is updated recursively based on historical trustworthiness and anomaly penalty items: ; in, Indicates the first Each device at time The reliability of the equipment. This indicates the device's reliability at the previous moment. Indicates the historical memory coefficient. Indicates the current observation confidence level Indicates the first Has a class of exceptions occurred? Indicates the first Severity of punishment for abnormal events This represents a truncation function that limits the confidence level to a preset range.

7. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 6, characterized in that, The abnormal events include one or more of the following: identity authentication failure, inconsistent APP fingerprint, abnormal timing deviation, serial number rollback, message authentication code verification failure, inconsistent control command semantic digest, control command physical constraint gating failure, abnormal communication frequency, and abnormal business operation status.

8. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 1, characterized in that, The formula for calculating reliable safety strength is: ; in, Indicates time Reliable safety strength; Indicates the physical constraint gating factor; Indicates the reliability of the equipment; This represents the business risk potential function value; Indicates data sensitivity; Indicates network link risk. The larger the value, the higher the current need for enhanced security. Security policies are adaptively selected based on the strength of reliable security: ; in, Indicates time The security strategy adopted This indicates a lightweight integrity verification strategy. Indicates the session key encryption strategy. This indicates a joint verification strategy involving signature, encryption, time window, and instruction constraints. This indicates a strong authentication, short-cycle key rotation, control restrictions, or device isolation policy. , , This indicates the threshold for switching security policies.

9. The adaptive method for trusted security of campus microgrids based on source-grid-load-storage constraints according to claim 8, characterized in that, Session keys are derived from the device composite identity, a random number, device trustworthiness, security policies, and policy versions. ; in, Indicates the first Each device at time Dynamic session key, This represents the key derivation function. This indicates the initial key material for the device. Represents a terminal random number. Represents a random number for the edge gateway. Represents the communication sequence number; Indicates the version of the cloud security policy; The edge gateway encrypts, authenticates, and protects the integrity of different business data and control commands according to the selected security policy. The message authentication code is: ; in, Indicates the message authentication code. Indicates the message header, Indicates message payload, Represents a timestamp. Indicates the serial number. This indicates the current security policy.

10. A trusted security adaptive system for a campus microgrid based on source-grid-load-storage constraints, implementing the trusted security adaptive method for a campus microgrid based on source-grid-load-storage constraints as described in any one of claims 1-9, characterized in that, It includes a cloud security management center, an edge security gateway, an endpoint security agent, a control command trust verification module, a business risk potential function calculation module, a device trust recursion module, a security policy adaptive decision-making module, and a log auditing module; The cloud-based security management center is used to perform device registration, composite identity management, policy version management, and global trustworthiness updates. The edge security gateway is used to perform two-way authentication, remote timing verification, dynamic session key derivation, trusted verification of control commands, data encryption, and anomaly handling. The terminal security agent is deployed in photovoltaic inverters, energy storage cabinets, charging piles, V2G charging piles, flexible load controllers or microgrid monitoring devices to complete identity authentication response, data encryption upload, control command decryption verification and execution result feedback. The control command trust verification module is used to verify the identity legitimacy, time validity, semantic consistency, and physical executability of control commands. The business risk potential function calculation module is used to calculate the nonlinear business risk potential function; The device credibility recursion module is used to update the device credibility based on the current observation credibility, historical credibility, and abnormal event penalty items; The security policy adaptive decision-making module is used to select a security policy based on the reliability and security strength. The log auditing module is used to record authentication logs, timing verification logs, key rotation logs, instruction verification logs, encrypted transmission logs, and exception handling logs.