Digital twin safety system of key infrastructure

By constructing a multi-module collaborative digital twin security system, the problem of insufficient collaboration in the modular architecture of critical infrastructure was solved, and real-time linkage between data flow efficiency and security protection was achieved, significantly improving the system's protection capabilities and response efficiency.

CN224037373UActive Publication Date: 2026-03-24GP CAPITAL GROUP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Digital twin systems for critical infrastructure suffer from insufficient modular architecture and coordination, leading to a disconnect between data processing and security protection. This results in the inability to achieve real-time and accurate twin mapping and effective protection, as well as delayed anomaly response and inefficient situation assessment.

Method used

A digital twin security system is constructed through multi-module collaborative design, including a multi-source heterogeneous data acquisition module, a secure transmission module, a digital twin modeling engine, a security protection module, and a visualization interaction module. Edge computing nodes are used to realize data preprocessing and hierarchical control, and combined with a hardware-level collaborative protection system, a deep coupling between data flow efficiency and security protection is achieved.

Benefits of technology

It significantly reduces end-to-end data latency, improves data flow efficiency, achieves 100% interception of virtual attacks, improves the accuracy of identifying hidden faults, and significantly shortens the emergency response time for operations and maintenance personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN224037373U_ABST
    Figure CN224037373U_ABST
Patent Text Reader

Abstract

The utility model relates to the technical field of safety protection of information technology and physical infrastructure fusion, in particular to a digital twin safety system of a key infrastructure. The system is composed of a multi-source heterogeneous data acquisition module, a secure transmission module, a digital twin modeling engine, a security protection module and a visual interaction module. The multi-source heterogeneous data acquisition module is in butt joint with a target facility through a wired / wireless dual-mode communication interface; the secure transmission module is configured with a physically isolated data channel; the digital twin modeling engine comprises a parallel processor array and a storage medium; the safety protection module is provided with a bidirectional data bus which is respectively connected with the digital twin modeling engine and the visual interaction module; the visual interaction module comprises a display terminal and an alarm unit. According to the utility model, full-chain safety guarantee from physical perception to virtual protection is realized through cooperation of multiple modules.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The utility model relates to the security protection technical field of information technology and physical infrastructure fusion, especially to a digital twin security system of critical infrastructure. BACKGROUND

[0002] With the acceleration of the intelligent transformation of new infrastructure, key infrastructures such as power, transportation, and energy gradually build digital twin systems to realize operation state monitoring.

[0003] The current digital twin system of critical infrastructure generally has the technical defect of insufficient modularity architecture collaboration, specifically, there is a lack of hardware-level collaboration mechanism among data acquisition, transmission, modeling, protection, and interaction modules, leading to disconnection between data processing and security protection. For example, the sensor network and the modeling engine cannot achieve real-time and accurate twin mapping due to the mismatch between communication protocols and computing power allocation; the security protection unit and the physical infrastructure do not form a closed-loop verification link, making it impossible to block the penetration of virtual layer attacks to physical devices; at the same time, the functions of edge computing and visualization modules are fragmented, resulting in delayed abnormal response and low efficiency of situation judgment. This systematic lack of collaboration seriously hinders the safe and reliable application of digital twin technology in critical infrastructure, and it is urgent to upgrade the whole-chain protection capability through integrated hardware architecture design and deep linkage mechanism among modules. SUMMARY

[0004] The utility model provides a kind of digital twin system fusing hardware-level security architecture and intelligent analysis technology, and the whole-chain security guarantee from physical perception to virtual protection is realized by multi-module collaboration.

[0005] The technical scheme adopted by the utility model is: a digital twin security system of critical infrastructure is composed of multi-source heterogeneous data acquisition module, security transmission module, digital twin modeling engine, security protection module and visualization interaction module,

[0006] The multi-source heterogeneous data acquisition module is connected to the target facility through wired / wireless dual-mode communication interface; the security transmission module is configured with a physically isolated data channel and is connected to the multi-source heterogeneous data acquisition module; the digital twin modeling engine includes a parallel processor array and a storage medium, and the input end is connected to the security transmission module; the security protection module has a bidirectional data bus connected to the digital twin modeling engine and the visualization interaction module respectively; the visualization interaction module includes a display terminal and an alarm unit, wherein data preprocessing and hierarchical control are realized among each module through edge computing nodes.

[0007] As a further improvement of the utility model, the multi-source heterogeneous data acquisition module contains a vibration sensor group, a temperature sensor array, a video acquisition unit and at least two industrial protocol converters arranged on the target facility body, and a data cleaning unit is arranged in the edge computing node to remove abnormal sampling values.

[0008] As a further improvement of the utility model, the secure transmission module contains a time sequence encryption unit and a blockchain verification node, and the physical isolation channel adopts a double buffer architecture design and is configured with a dynamic bandwidth allocator.

[0009] As a further improvement of the utility model, the parallel processor array of the digital twin modeling engine contains at least three heterogeneous computing units, and the storage medium is solidified with a self-correcting modeling algorithm and is configured with a real-time data mapping interface.

[0010] As a further improvement of the utility model, the security protection module is integrated with an abnormal mode recognition unit and a dynamic access controller, and the bidirectional data bus is configured with a dual identity authentication mechanism and a traffic shaping device.

[0011] As a further improvement of the utility model, the visual interaction module contains a three-dimensional situation reconstruction unit and a prediction and deduction component, and the display terminal is integrated with a touch layer and is configured with a multi-stage alarm indicator light array.

[0012] The utility model has the advantages that: the utility model realizes the deep coupling and real-time linkage of data acquisition, transmission, modeling, protection and interaction modules by constructing a hardware-level cooperative protection system, and synchronously improves the data flow efficiency and security protection strength based on the hierarchical control mechanism of the edge computing node and the physical isolation channel between the modules, effectively blocks the penetration path of virtual attacks to the physical facilities while ensuring the high-precision real-time mapping of the digital twin model, and solves the response lag and blind area problems caused by the modular architecture of the traditional system. BRIEF DESCRIPTION OF DRAWINGS

[0013] Figure 1 It is a system block diagram of the digital twin security system of a key infrastructure. DETAILED DESCRIPTION

[0014] In order to make the technical problems, technical schemes and beneficial effects of the present application clearer, the present application will be further described in detail below with reference to the drawings and examples. It should be understood that the examples described herein are only used to explain the present application and do not limit the present application.

[0015] The utility model provides a kind of digital twin security system of key infrastructure, is composed of multi-source heterogeneous data acquisition module, secure transmission module, digital twin modeling engine, security protection module and visual interaction module.

[0016] The multi-source heterogeneous data acquisition module is connected with the target facility through a wired / wireless dual-mode communication interface; the secure transmission module is configured with a physically isolated data channel and connected with the multi-source heterogeneous data acquisition module; the digital twin modeling engine includes a parallel processor array and a storage medium, and the input end is connected with the secure transmission module; the security protection module has a bidirectional data bus connected with the digital twin modeling engine and the visual interaction module respectively; the visual interaction module includes a display terminal and an alarm unit, wherein data preprocessing and hierarchical control are realized through an edge computing node between the modules.

[0017] The multi-source heterogeneous data acquisition module includes a vibration sensor group, a temperature sensor array, a video acquisition unit and at least two industrial protocol converters arranged in the target facility body, and a data cleaning unit is built in the edge computing node of the multi-source heterogeneous data acquisition module to eliminate abnormal sampling values.

[0018] The secure transmission module includes a time sequence encryption unit and a blockchain verification node, the physically isolated channel adopts a double buffer architecture design and is configured with a dynamic bandwidth allocator.

[0019] The parallel processor array of the digital twin modeling engine includes at least three heterogeneous computing units, the storage medium is solidified with a self-correcting modeling algorithm and is configured with a real-time data mapping interface.

[0020] The security protection module integrates an abnormal mode recognition unit and a dynamic access controller, and the bidirectional data bus is configured with a dual identity authentication mechanism and a traffic shaping device.

[0021] The visual interaction module includes a three-dimensional situation reconstruction unit and a prediction and deduction component, and the display terminal integrates a touch layer and is configured with a multi-stage alarm indicator light array.

[0022] Embodiment:

[0023] Taking the deployment of a certain ultra-high voltage converter station digital twin safety system as an example, the specific implementation manner is as follows.

[0024] (I) Hardware deployment

[0025] Multi-source heterogeneous data acquisition module: Install vibration sensor groups (using MEMS three-axis acceleration sensors with a range of ±10g) and infrared temperature sensor arrays (accuracy ±0.5℃) at key positions of converter transformers, circuit breakers, and grounding grids. Configure an industrial gateway supporting Modbus TCP and OPC UA dual protocol conversion in the station. The edge computing node uses a NVIDIA Jetson TX2 embedded platform. The built-in data cleaning unit is based on the Z-score algorithm, which filters out abnormal sampling values outside the ±3σ range in real time.

[0026] Secure transmission module: Use optical fiber and 5G dual-mode physical isolation channels. Configure a dual-buffer architecture (each buffer capacity is 128MB). The time sequence encryption unit is equipped with the SM4 algorithm. The blockchain verification node is built based on the Hyperledger Fabric framework. The dynamic bandwidth allocator divides the transmission queue according to data priority (modeling data has the highest priority and allocates 60% of the bandwidth).

[0027] Digital twin modeling engine: The parallel processor array is composed of three types of heterogeneous computing units: FPGA (Xilinx Zynq UltraScale+), GPU (NVIDIA A100), and DSP (TI TMS320C6678). The storage medium loads the device life prediction model based on the LSTM neural network as a self-correcting modeling algorithm. The real-time data mapping interface supports synchronous updates of 2000 data points per second.

[0028] Security protection module: The anomaly pattern recognition unit deploys an intrusion detection model based on the Isolation Forest algorithm. The dynamic access controller sets a device operation whitelist (only allows authorized IP segments to access). The bidirectional data bus enables RSA-2048 and fingerprint recognition dual authentication. The traffic shaping device limits the uplink rate of each node to no more than 10Mbps.

[0029] Visual interaction module: A 55-inch LED touch screen integrates a capacitive touch layer (supports 10-point touch). The three-dimensional situation reconstruction unit builds a panoramic model of the converter station based on the Unity3D engine. The prediction and deduction component has a Monte Carlo simulation module. The multi-level alarm indicator has a three-color LED array divided by risk level: red (emergency), orange (high risk), and yellow (warning).

[0030] (II) System operation process

[0031] Step one: The vibration sensor detects 9.5g abnormal vibration (normal threshold <5g) in phase C of the converter transformer. After data cleaning by the edge node, the secure transmission module sends it to the modeling engine through the physical isolation channel. The time sequence encryption unit adds a timestamp (accuracy ±1ms) to the data packet. The blockchain node generates a hash value and writes it to the distributed ledger.

[0032] Step two: The FPGA unit of the modeling engine analyzes the vibration spectrum characteristics in real time, the GPU unit compares the historical fault library (containing 327 typical fault samples), the DSP unit calculates the device health index (from 85.2 to 62.4), and triggers the self-correcting algorithm to update the winding looseness fault prediction model.

[0033] Step three: The security protection module detects abnormal access requests (source IP not in the whitelist), and the dynamic access controller immediately cuts off the session link, and sends an encrypted alarm instruction (using AES-256 encryption) to the visualization module through the bidirectional data bus.

[0034] Step four: The visualization interaction module highlights the C-phase transformer position in the three-dimensional interface, and the fault diagnosis report (predicted winding looseness probability 92.7%) pops up on the touch layer, the red alarm light starts the stroboscopic mode (frequency 2Hz), and the prediction and deduction component generates the future 2-hour fault development curve (confidence >90%).

[0035] (Three) Implementation effect verification

[0036] The comparison test after deployment shows that: (1) the data end-to-end delay is reduced from 380ms of the traditional system to 95ms (increased by 75%); (2) the interception rate of virtual attack penetration attempts reaches 100% (the control group is 68%); (3) the accuracy of hidden fault identification is improved to 93.6% (the original system is 79.2%); (4) the average emergency response time of operation and maintenance personnel is shortened to 42 seconds (originally 3 minutes and 15 seconds).

[0037] As can be seen from the above examples, the system significantly optimizes the security protection and response efficiency of the key basic digital twin system. First, by building a hardware-level cooperative protection system, it realizes the deep coupling and real-time linkage of data acquisition, transmission, modeling, protection and interaction modules, significantly reducing the data end-to-end delay and improving the data flow efficiency. Second, the abnormal pattern recognition unit of the security protection module and the dynamic access controller effectively cooperate to achieve 100% interception of virtual attack penetration attempts, significantly enhancing the security protection strength of the system. Third, the self-correcting modeling algorithm of the digital twin modeling engine combined with the real-time data mapping interface significantly improves the identification accuracy of hidden faults, providing more accurate fault diagnosis information for operation and maintenance personnel. Finally, the three-dimensional situation reconstruction unit of the visualization interaction module and the prediction and deduction component, combined with the real-time feedback of the multi-level alarm indicator, significantly shortens the emergency response time of the operation and maintenance personnel, improving the emergency response efficiency.

[0038] In conclusion, the digital twin security system of the key infrastructure provided by the utility model has shown excellent performance and remarkable improvement effect in practical application. In order to further verify its implementation effect, we have carried out multiple rounds of comparative tests and collected a large amount of data for analysis. The test results show that the system not only greatly reduces the data end-to-end delay, but also realizes efficient interception of virtual attack penetration attempts, improves the identification accuracy of hidden faults, and significantly shortens the emergency response time of operation and maintenance personnel. These remarkable improvement effects fully prove the effectiveness and practicality of the utility model, and provide strong technical support for the safety protection of key infrastructure.

[0039] The above examples are only used to illustrate the technical solutions of the utility model, but not to limit them; although the utility model has been described in detail with reference to the foregoing examples, those skilled in the art should understand that the technical solutions recorded in the foregoing examples can still be modified, or some technical features can be replaced equivalently; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the utility model examples.

Claims

1. A digital twin security system for critical infrastructure, characterized by: The multi-source heterogeneous data acquisition module, the secure transmission module, the digital twin modeling engine, the security protection module, and the visual interaction module are connected through the edge computing node to realize data preprocessing and hierarchical control. The multi-source heterogeneous data acquisition module includes a vibration sensor group, a temperature sensor array, a video acquisition unit, and at least two industrial protocol converters deployed in the target facility body, and the edge computing node has a data cleaning unit built-in for rejecting abnormal sampling values.

2. The digital twin security system of critical infrastructure of claim 1, wherein: The secure transmission module includes a timing encryption unit and a blockchain verification node, and the physically isolated channel adopts a double buffer architecture design and is configured with a dynamic bandwidth allocator.

3. The digital twin security system of critical infrastructure of claim 1, wherein: The parallel processor array of the digital twin modeling engine includes at least three heterogeneous computing units, and the storage medium is solidified with a self-correcting modeling algorithm and is configured with a real-time data mapping interface.

4. The digital twin security system of critical infrastructure of claim 1, wherein: The security protection module integrates an abnormal pattern recognition unit and a dynamic access controller, and the bidirectional data bus is configured with a dual identity authentication mechanism and a traffic shaping device.

5. The digital twin security system of critical infrastructure of claim 1, wherein: The visual interaction module includes a three-dimensional situation reconstruction unit and a prediction and deduction component, and the display terminal integrates a touch layer and is configured with a multi-level alarm indicator light array.

6. The digital twin security system of critical infrastructure of claim 1, wherein: ​