Summary of the invention
The objective of the invention is provides a kind of power information acquisition system in order to overcome the deficiency of prior art, and the attack that it can effectively resist external hacker ensures self security of operation.
A kind of technical scheme that realizes above-mentioned purpose is: a kind of power information acquisition system comprises main website of system, collection terminal, and connects the communication channel between main website of said system and the said collection terminal; The operating system of main website of said system is (SuSE) Linux OS; Set up internal lan in the main website of said system, and with the host-host protocol of P2P agreement as said internal lan; Main website of said system comprises: preposition information collecting platform, application server and database server; Said database server connects said preposition information collecting platform and said application server respectively, and said preposition information collecting platform comprises communication interface machine and the preposition information collection server that connects successively; Said preposition information collection server connects said database server, and said communication interface machine connects said preposition information collection server, and main website of said system and said communication channel are isolated.
Further, said communication channel is a GPRS/CDNA public network channel; Said preposition information collecting platform also comprises fire wall and physical isolation apparatus, and said fire wall connects said communication interface machine, and said physical isolation apparatus connects said fire wall.
The program further again, that prepackage can be peeled off ICP/IP protocol in the said physical isolation apparatus.
Further, said communication channel is: optical fiber private network channel, medium voltage electricity carrier wire private network channel, 230 wireless private network channels, PSTN/ADSL special line channel.
Further, in the said preposition information collecting platform encryption equipment is set, said encryption equipment is parallelly connected with said preposition information collection server.
Further, said collection terminal comprises: concentrator, collector and electric energy meter, and said concentrator connects said communication channel, and some collectors connect said concentrator through the power carrier line, and each concentrator is through the some electric energy meters of RS485 private line access.
Further, said collection terminal comprises: concentrator and carrier electric energy meter, and said concentrator connects said communication channel, and said concentrator is through the some said carrier electric energy meters of power carrier private line access.
Adopted the technical scheme of a kind of power information acquisition system of the present invention, promptly the operating system of main website of system is (SuSE) Linux OS; Set up internal lan in the main website of said system, and with the technical scheme of P2P agreement as the host-host protocol of said internal lan.Its technique effect is: it can effectively resist hacker and disabled user's attack, thereby ensures the security of operation of self.
Embodiment
See also Fig. 1 and Fig. 2,, pass through embodiment particularly below, and combine accompanying drawing at length to explain in order to understand technical scheme of the present invention better:
See also Fig. 1 and Fig. 2, a kind of power information acquisition system of the present invention, comprise main website of system 1, collection terminal 2 and connect main website of said system 1 and said collection terminal 2 between communication channel 3.
Main website of said system 1 has functions such as power information collection, WT-MSR exception monitoring, checks meter etc. the power information basic data is provided for remote control terminal carries out electrical energy consumption analysis, power information issue, market forecast, the electricity charge.
Set up internal lan in the main website of said system 1, and with the host-host protocol of P2P agreement as said internal lan, main website of said system 1 adopts (SuSE) Linux OS as operating system.Adopt the purpose of P2P agreement and (SuSE) Linux OS to be to improve the ability that said power information acquisition system is resisted external assault.Main website of said system 1 also connects remote control terminal, and main website of said system 1 combines the mode of middle database to be connected with remote control terminal through Webservice to communicate.
Main website of said system 1 comprises preposition information collecting platform 11, application server 12 and database server 13; Said application server 12 and said database server 13 be the built-in disk array all; Said preposition information collecting platform 11, said application server 12 connect said database server 13 simultaneously; Said preposition information collecting platform 11 communicates with said database server 13; Said preposition information collecting platform 11 effects are in the disk array with the said database server 13 of electricity consumption data typing; Simultaneously, through being connected of said database server 13 and remote control terminal, checking meter etc. the power information basic data is provided for remote control terminal carries out electrical energy consumption analysis, power information issue, market forecast, the electricity charge.Said in addition database server 13 also has intrusion detection capability and anti-virus ability, and data self-timing every day in the said disk array is carried out the data redundancy backup.Be stored in the disk array of the backup server (not shown) that links to each other with said database server 13.
Said application server 12 can carry out two-way communication with said database server 13; The effect of said application server 12 is to receive the electricity consumption data in the disk array of said database server 13; Said electricity consumption data are analyzed; In time find multiplexing electric abnormality and the unusual situation of WT-MSR; Again said analysis result is fed back to said database server 13, pass to remote control terminal by said database server 13 again, and said multiplexing electric abnormality and the unusual user of WT-MSR are made operated from a distance by said remote control terminal.
Said main website 1 also comprises the workstation (not shown); The effect of said workstation is: the effect of said workstation 7 mainly is: the system file of preserving said (SuSE) Linux OS in the disk array of said workstation, said disk array redundant configuration.Said workstation is also managed the work and the operation of main website of said system 1.Said workstation can also be made amendment to some parameters of said collection terminal 2, like pre-payment parameter, period, ladder electric price parameter etc., and said collection terminal 2 is sent steering order, like load control, pre-payment control etc.Before carrying out aforesaid operations, said workstation can verify that what checking was adopted is software mode, like the secondary password authentication to operating personnel; Perhaps the two-stage security authentication mechanism of software and hardware combining like electronics mobile cryptographic key or U shield etc., is guaranteed the security control operation to said workstation.Operating process information needs detail record, and long preservation is in the disk array of said workstation.
The media that the internal lan that said preposition information collecting platform 11 is main websites of said system 1 is connected with said communication channel 3, said information collecting platform 11 comprise the preposition information collection server 112 and communication interface machine 111 that connects successively.Said preposition information collection server 112 connects said database server 13 and said application server 12 respectively.The second fire wall (not shown) and the 3rd fire wall (not shown) can also be set respectively between said preposition information collection server 112 and said database server 13 and the said application server 12.Can only have access to said preposition information collection server 112 from user in public outer net and the power information outer net.Power information from said collection terminal 2 is stored in earlier in the disk array that is built in said preposition information collection server 112.Because being the form with packet, said power information passes to said preposition information collection server 112; Therefore the another one effect of said preposition information collection server 112 is the said power information bag conversion operations that decompresses is converted into the electricity consumption data that said database server 13 can be discerned.For said electricity consumption data are not being distorted in said database server 13 transmittance processs, said power information is also through encrypting with said preposition information collection server 112 parallelly connected encryption equipment (not shown).Said preposition information collection server 112 can also receive order and the control command of said workstation through the parameter modification of institute's application server 12 transmission; Be kept in its disk array; Through said communication channel 3, accomplish said collection terminal 2 parameter modifications and control again.The effect of said preposition information collection server 112 also is to confirm the collection of said collection terminal 2 completion power informations.
Said communication interface machine 111 connects said communication channel 3 through dual mode.The dual mode that is connected with of said preposition information collecting platform 11 and said communication channel 3:
A kind of mode is that said communication interface machine 111 directly connects said communication channel 3; Can comprise with said communication interface machine 111 direct-connected communication channels 3: optical fiber private network channel 31,230 wireless private network channels 33, medium voltage electricity carrier wire private network channel 23 and PSTN/ADSL special line channel 34 etc., these communication channels all belong to the electric power private communication channel.
The equipment of isolating between internal lan that said communication interface machine 111 is said main station systems 1 and the said communication channel 3; Said communication interface machine 111 communicates with said information acquisition end 2 through said communication channel 3 downwards; Said communication interface machine 111 is delivered to said power information in the said preposition information collection server 112 after said power information is installed additional the P2P agreement.
A kind of in addition mode is: said communication interface machine 111 connects fire wall 113 earlier; Said fire wall 113 connects physical isolation apparatus 114 again; Said physical isolation apparatus 114 connects said communication channel 3, and the said communication channel 3 here is a GPRS/CDMA public network channel 35.Because GPRS/CDMA public network channel 35 belongs to the public network channel, therefore something must be done to, prevents that said internal lan from suffering the assault from public network.One of measure is that fire wall 113 is set, and said fire wall 113 can be resisted most assault from public network.But present development trend is increasing attack from public network all is to take place having under the situation of fire wall, therefore physical isolation apparatus 114 must be set again, with said internal lan and 35 forced quarantines of said GPRS/CDMA public network channel.
Said physical isolation apparatus 114 its concrete principle of work are: be connected said physical isolation apparatus 114 through forbidding said GPRS/CDMA public network channel 35 simultaneously with said internal lan, prevent hacker's attack.Said physical isolation apparatus 114 can with the situation of said internal lan suspension under; That adopts said physical isolation apparatus 114 prepackages can force to peel off ICP/IP protocol with the program that ICP/IP protocol is peeled off from said power information; See through said physical isolation apparatus 114, said fire wall 113 again, install non-ICP/IP protocol such as P2P agreement additional through said communication interface machine 111 after, pass to said preposition information collection server 112; The transmission mechanism of said physical isolation apparatus 114 has non-programmable characteristic, therefore can prevent main website of said system 1 infective virus.
Simultaneously, said physical isolation apparatus 114 has been cancelled system call command and interception system call instruction in said (SuSE) Linux OS, and adopts and force access mechanism, and limiting command is carried out authority; Further improved the ability of the strick precaution of said physical isolation apparatus from the public network assault.
In the present embodiment, said fire wall 113 is the VPN fire wall.It is to use physics fire wall the most widely at present.
In order to guarantee the security of operation of said main website, also taked following measures:
Main website of said system 1 also is equipped with ups power, guarantees under powering-off state, can work on.
On said preposition acquisition server 111, said application server 12 and the said data server 13 software firewall and anti-virus software have been installed all; And upgrade in time patch and virus base; Said preposition acquisition server 111, said application server 12 and said data server 13 softwares are installed and used and carry out necessary monitoring, prevent to install the software that has potential safety hazard.
Nucleus equipments such as said preposition acquisition server 111, said application server 12 and said data server 13 need redundant configuration, eliminate the Single Point of Faliure of key node.Said redundant measure comprises disk array etc.
The framework of said collection terminal 2 is divided into four kinds:
First kind of framework comprises concentrator 211, collector 212 and electric energy meter 213; Said concentrator 211 connects said communication channel 3; Several said collectors 212 connect a said concentrator 211 through carrier line respectively, and some electric energy meters 213 are through said collector 212 of RS485 private line access.Said electric energy meter 213 will be gathered user's power information; And pass to said collector 212; Pass to said concentrator 211 by said collector 212 again, through said communication channel 3 said power information is passed to main website of said system 1 by said concentrator 211 again.
In second kind of framework, comprise concentrator 221 and carrier electric energy meter 222, said concentrator 211 connects said communication channel 3, and some said carrier electric energy meters 222 connect said concentrator 221 through carrier line.Said carrier electric energy meter 222 will be gathered user's power information, and pass to said concentrator 221, through said communication channel 3 said power information passed to main website of said system 1 by said concentrator 211 again.In the said framework, unified standard carrier communication stipulations are improved transistroute algorithm, routing iinformation and are learnt automatically and optimal design.For period of checking meter of the concentrator interference of avoiding checking meter of can staggering of the platform district that possibly crosstalk, thereby improve meter reading efficiency.Cryptoguard is set simultaneously, or communication packet means such as encrypt are guaranteed that communication process is safe and punctual, guarantee that data are not by intercepting midway or modification.
In two above-mentioned frameworks, said electric energy meter 213 can be a prepayment meter, and said carrier electric energy meter 222 can be the pre-payment carrier electric energy meter, and said electric energy meter 213 all belongs to single-phase electric energy meter with said carrier electric energy meter 222.
Said carrier line can be the bandwidth carrier circuit, also can be the narrowband carrier circuit.
These two kinds of frameworks are used for rural area irrigation and drainage user, resident, bulk sale family, the single-phase user of general industry, general industry three-phase user and industrial distribution transforming critical point stoichiometric point.
The third framework comprises special transformer terminals 231 and power measuring terminal 232; Said power measuring terminal 232 passes to said special transformer terminals 231 with the power information of gathering, and by said transformation terminal 231 power information is crossed said communication channel 3 more said power information is passed to main website of said system 1.It is used for specially becoming the user.
Last a kind of remote collection terminal 24 that comprises, said remote collection terminal 24 pass to main website of said system 1 directly through said communication channel 3 with the user power utilization information of gathering.
Said electric energy meter 213, said carrier electric energy meter 222, said power measuring terminal 232 and said remote collection terminal 24 built-in data storage storage chips; For important historical data, back-up storage arranged, the historical data when guaranteeing the equipment malfunction is complete.Take into full account said electric energy meter 213, said carrier electric energy meter 222, said power measuring terminal 232 and the monitoring of said remote collection terminal 24 abnormal operating conditions and anomalous event record and the function that reports.Be convenient to the abnormal conditions that said main website 1 in time finds collecting device, prevent the generation of potential safety hazard.Simultaneously; On said electric energy meter 213, said carrier electric energy meter 222, said power measuring terminal 232 and the said remote collection terminal 24 encryption chip is set; So that they carried out the parameter setting, verifying when control is carried out, to improve the security of said power information acquisition system.Said electric energy meter 213, said carrier electric energy meter 222, said power measuring terminal 232 and said remote collection terminal 24 will increase the Authority Verification function on software design, have only through just carrying out important operation after the legal checking.
Those of ordinary skill in the art will be appreciated that; Above embodiment is used for explaining the present invention; And be not to be used as qualification of the present invention; As long as in connotation scope of the present invention, all will drop in claims scope of the present invention variation, the modification of the above embodiment.